Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3711 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.49%—Oracle Webcenter Content17/6/202618/6/2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While…
ModificadaMedia (5.7)0.15%—Powerschool Employee Access Center16/6/202630/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in…
Pendiente de análisisAlta (8.8)0.45%—Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI16/6/20261/10/2026
Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high…
ModificadaMedia (4.6)0.26%—Qnap License Center10/6/202623/7/2026
A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and…
AnalizadaMedia (5.1)0.16%—Qnap Notification Center10/6/20265/8/2026
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later
AnalizadaAlta (7.1)0.39%—Schneider-electric Struxureware Data Center Expert9/6/202620/7/2026
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
Pendiente de análisisAlta (7.8)0.15%—Genetec Security CenterAI2/6/202622/7/2026
A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.…
AplazadaAlta (7.1)0.43%—HP Service CenterAI29/5/202621/7/2026
Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific query function to access other users' EC order details.
AplazadaMedia (4.6)0.20%—Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI26/5/202624/7/2026
Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi…
AnalizadaMedia (6.8)0.12%💥 PoCAcer Care Center25/5/202623/7/2026
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit…
ModificadaAlta (7.8)0.37%—Microsoft Windows Admin Center20/5/202623/7/2026
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (8.2)0.28%—Talend Administration CenterAI20/5/202623/7/2026
A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available.
AplazadaMedia (5.4)0.23%—Talend Administration CenterAI20/5/202623/7/2026
A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user.
Pendiente de análisisAlta (7)0.22%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.
Pendiente de análisisMedia (6.9)0.22%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.
Pendiente de análisisAlta (8.4)0.21%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions only.
Pendiente de análisisMedia (5.1)0.31%—Powersystem CenterAI12/5/202617/6/2026
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication.
AnalizadaAlta (8.8)0.78%—Microsoft Windows Admin Center12/5/202617/6/2026
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.3)0.63%—Microsoft Windows Admin Center12/5/202617/6/2026
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially…
Pendiente de análisisCrítica (9.3)0.13%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…
Pendiente de análisisAlta (7.3)0.20%—Siemens Simcenter FemapAI12/5/20267/10/2026
Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
AnalizadaAlta (8.7)0.39%—Siemens Teamcenter12/5/202617/6/2026
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application contains hardcoded key which is used…
AnalizadaAlta (8.5)0.28%—Siemens Teamcenter12/5/202617/6/2026
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (All versions < V2412.0009), Teamcenter V2506 (All versions < V2506.0005), Teamcenter V2512 (All versions). The affected application does not properly encode or filter…